Skip to content

Set Up Microsoft SSO

Microsoft SSO lets users sign in to their Wombat account using a Microsoft account. Wombat uses the Microsoft identity provider and requests the delegated User.Read permission to identify the signed-in user and read their basic profile.

Wombat does not import Microsoft groups, roles, or permissions. A user must still be created in Wombat and assigned the appropriate Wombat role and access.

Before You Start

Identify two administrators. They may be the same person:

  • A Wombat administrator who can create users and assign Wombat permissions.
  • A Microsoft Entra administrator who can review or approve the Wombat application if your organization's consent policy requires it.

Before the first sign-in:

  1. Create the administrator in Wombat using the same primary email address they use for their Microsoft account.
  2. Make sure the Wombat user is active and has the required administrator permissions.
  3. Confirm that the Microsoft account is active and permitted to use third-party enterprise applications.
  4. Ask your Microsoft Entra administrator whether user consent is allowed. If it is not, plan for the administrator to approve the application during the first sign-in attempt.

Email addresses must match

Use the email returned by the Microsoft account, not an unverified alias or a different Microsoft account. A mismatch can create an account-linking error or result in a successful Microsoft sign-in with no Wombat access.

First Administrator Sign-In

The first Wombat administrator should complete the following steps before Microsoft SSO is announced to other users:

  1. Open the Wombat sign-in page in a private browser window. This avoids accidentally selecting an existing personal Microsoft session.
  2. Select Microsoft.
  3. Choose the expected account. Wombat asks Microsoft to show the account picker, so seeing this choice is normal.
  4. Complete your organization's Microsoft sign-in requirements, such as multifactor authentication or Conditional Access.
  5. Review the requested permission and accept it if your organization allows user consent.
  6. If Microsoft shows Need admin approval or Approval required, stop and have a Microsoft Entra administrator approve the request. Retry the sign-in after approval.
  7. Allow Wombat to return to the sign-in page and finish linking the account. The first sign-in may show a Linking your account message and may redirect through Microsoft a second time.
  8. Confirm that Wombat opens the expected organization, tenant, division, or site and that the administrator can access the required administration pages.

When Wombat uses its server-side account-linking flow, it queues a New Login Method email. Links completed through Microsoft's standard provider-linking flow may not generate this email. Future sign-ins use the same Microsoft button and normally do not repeat the linking step.

The User.Read delegated permission does not normally require tenant-wide administrator consent. Administrator approval is not required when your organization's policy allows the user to consent to Wombat, or when individual or tenant-wide consent was already granted. However, your organization's application consent policy may prevent users from approving new applications.

If administrator approval is required, the Entra administrator should:

  1. Review the application name, publisher, and requested permissions shown by Microsoft.
  2. Approve the pending request through the organization's normal application approval process, or grant tenant-wide consent from Microsoft Entra admin center > Entra ID > Enterprise apps > All applications > [Wombat application] > Security > Permissions.
  3. If the enterprise application requires user assignment, assign the pilot administrator and the users or groups that need Wombat access.
  4. Ask the pilot administrator to sign in again from a private browser window.

See Microsoft's documentation for user and administrator consent and granting tenant-wide administrator consent.

Roll Out Microsoft SSO

After the administrator test succeeds:

  1. Create or import each user in Wombat before asking them to sign in.
  2. Use the same primary email address stored in Microsoft Entra ID.
  3. Assign each user a Wombat role, permissions, and the correct organization, tenant, division, or site access.
  4. Ask a small pilot group to sign in with Microsoft and confirm their landing location and access.
  5. Send the sign-in instructions to the remaining users.

For a new Wombat user who has never signed in, the first Microsoft sign-in normally links automatically. The user's Microsoft password and multifactor authentication settings remain managed by Microsoft and are not stored in Wombat.

Existing Wombat Accounts

An existing user may already have a password, Google, or Microsoft login method linked to the same email address. Wombat will not silently replace an established login method.

Depending on the account state, the user may be asked to:

  • Sign in with the existing method so Wombat can verify ownership and link Microsoft.
  • Complete the Linking your account flow and return to Microsoft.
  • Contact Wombat Support so a temporary Microsoft-linking window can be opened.

A support-authorized linking window lasts 24 hours. The user must use the emailed sign-in link and complete the Microsoft sign-in before it expires. Opening a linking window authorizes an additional login method; it does not remove the user's existing method.

What Users Should Expect

  • Selecting Microsoft redirects the browser to Microsoft's sign-in page and then back to Wombat.
  • Microsoft may require multifactor authentication, device compliance, location checks, or other Conditional Access controls.
  • The Microsoft account picker may appear even when the user is already signed in.
  • A consent screen may appear on the first sign-in unless an administrator has already granted consent.
  • New accounts may briefly show an account-linking dialog and perform a second redirect.
  • Users linked through Wombat's server-side linking flow receive an email when Microsoft is added as a login method. Other successful linking paths may not send this email.
  • Wombat access is controlled by the user's Wombat status and permissions, not by Microsoft group membership.

Troubleshooting

SymptomLikely causeWhat to do
Microsoft shows Need admin approval or Approval requiredThe organization's user-consent policy blocks the applicationSubmit the approval request or have a Microsoft Entra administrator review and grant consent, then retry
Microsoft says the user is not assigned to the applicationThe enterprise application requires user assignmentAssign the user or an appropriate group to the Wombat enterprise application in Microsoft Entra ID
An AADSTS50020 or wrong-tenant message appearsThe browser selected a personal account, guest identity, or account from another Microsoft tenantSign out of Microsoft and retry in a private window with the expected work or school account
Wombat says the account already has another login providerThe email is already linked to a previously used password, Google, or Microsoft identityFollow the prompt to sign in with the existing method; if that is not possible, contact Wombat Support for a 24-hour Microsoft-linking window
The linking email no longer worksThe temporary linking window expiredAsk Wombat Support to issue a new link and complete it within 24 hours
Microsoft sign-in succeeds, but Wombat shows no access or the wrong locationThe Wombat user was not provisioned, is inactive, has different email data, lacks permissions, or has another default locationVerify the user's email, active status, Wombat permissions, and organization or site assignments
The first sign-in loops or remains on loadingThe redirect state or browser site data is stale, or privacy software blocked part of the redirectClose extra Wombat tabs, retry in a private window, allow cookies and redirects for Wombat and Microsoft, and temporarily disable blocking extensions for the sign-in
Microsoft rejects the sign-in after the Wombat redirectConditional Access, multifactor authentication, device compliance, or sign-in-risk policy blocked the requestHave the Microsoft Entra administrator review the user's Microsoft sign-in logs and policy result
Wombat reports that the provider did not verify the email or could not link the accountMicrosoft returned an email or identity that does not safely match the existing Wombat accountConfirm the user's primary Microsoft email and Wombat email match, then contact Wombat Support rather than creating a duplicate user
The New Login Method email does not arriveThe account used Microsoft's standard provider-linking flow, or mail was filtered or delayedIf Microsoft sign-in succeeds, linking is complete. Otherwise, check junk and quarantine folders before contacting Wombat Support

Information to Collect for Support

If the issue continues, send Wombat Support:

  • The user's Wombat email address.
  • The Microsoft email address they selected.
  • The approximate time of the failed attempt and the user's time zone.
  • A screenshot or the complete Microsoft AADSTS error code, without passwords or authentication codes.
  • Whether the account can still sign in using password or Google.
  • Whether Microsoft Entra consent and user assignment have been completed.

Do not send passwords, multifactor authentication codes, access tokens, or ID tokens.